Skip to content
Open access

A Reliability-Aware Edge–Cloud Framework for Early Intrusion Detection in IoT Networks

Aug 2026 · Electronics · 0 citations · 27 references

TL;DR

A reliability-aware edge–cloud framework that treats early detection as a sequential routing problem, and identifies the minimum-evidence gate and cloud-refinement stage as the main reliability controls.

Abstract

Gateway-resident intrusion detection can act before IoT traffic reaches cloud services, but early decisions are based on incomplete flow prefixes. This paper presents a reliability-aware edge–cloud framework that treats early detection as a sequential routing problem. At each checkpoint, a lightweight gated recurrent unit (GRU) maps causal packet-prefix features to a malicious-probability estimate. Temperature scaling, asymmetric benign and malicious thresholds, and an eight-packet minimum-evidence gate determine whether a flow exits locally, remains under observation, or is sent for cloud refinement. Short and unresolved flows are classified by regularized logistic regression using a compact 97-feature causal representation. The edge model contains 19,777 parameters, and each cloud submission carries 388 bytes of float32 features. The principal evaluation uses all 309 CIC-IoT-2023 PCAP files under four outer PCAP-disjoint folds, with separate edge-training, calibration, cloud-development, and final-test roles. Across 2,286,754 pooled out-of-fold flows with 88.54% malicious prevalence, the framework resolves 422,190 flows at the edge and routes 1,864,564 for cloud refinement, reducing cloud submissions by 18.46%. The final policy attains 4.47% FPR, 1.89% FNR, 96.82% balanced accuracy, and 98.76% F1 score. Observation-budget analysis identifies 32 packets as a corpus-specific compromise, whereas controlled delays in post-eight-packet information expose the limits of short-prefix detection. On the balanced CICIDS2017 test set, in-domain development attains 97.03% balanced accuracy; zero-shot transfer falls to 86.30%, and target-calibration-only adaptation improves it to 91.65%. Ablation results identify the minimum-evidence gate and cloud-refinement stage as the main reliability controls. Benign false alarms, delayed post-eight-packet information, cross-dataset shift, and scenario/file-level labels remain the principal limitations.

Read PDF

Similar papers

Sep 2026

Service Interaction Profiling for Abnormal Communication Discovery in Cloud-Native Microservice Systems

Blockchain-enabled IoT networks can improve device authentication and data integrity, but IoT gateways remain vulnerable to abnormal traffic, flooding attacks, and unauthorized access attempts. Since gateway devices often operate with limited computing resources, anomaly detection models must provide high accuracy, low...

Wei-Jun Tan, Jia-Hui Lim, Marcus Yong Chen · 0 citations
Open access Aug 2026

A Three-Stage Federated Distillation Framework for Robust Intrusion Detection in Heterogeneous IoT/Edge Networks

The framework is presented as a bounded, server-assisted robustness-oriented training strategy for heterogeneous IoT/edge intrusion detection, and shows competitive primary performance and stronger robustness in several severe label-skew settings.

Xu-Dong Yang, Zikui Lin, Qiu-Yan Li et al. · 0 citations
Open access Jul 2026

A routing-signal study of confidence-gated conditional computation for lightweight IoT intrusion detection

Background Intrusion detection at Internet of Things (IoT) edge gateways must run under tight compute and memory budgets, motivating dual-path designs that classify most flows with a cheap model and escalate only uncertain flows to a heavier one. A prior conference study introduced such a system, in which a tiny mu...

Mahmoud Abbasi, Javier Prieto Tejedor, Carolina Villoria Torres et al. · 0 citations
Open access Aug 2026

Hybrid Intrusion Detection System with Real-Time Concept Drift Detection for Enhanced IoT Security

A hybrid IDS framework that integrates supervised Random Forest classification, unsupervised Isolation Forest anomaly monitoring, and Kolmogorov–Smirnov (KS)-based concept drift monitoring is presented, providing initial evidence of generalization to one held-out attack family but should not be interpreted as proof of...

Muath A. Obaidat, Meryem Abouali, Aneeza Shakeel · 0 citations
Open access Aug 2026

LLM-Integrated Anomaly Detection for IoT Networks: Framework Structure

A machine learning-based framework to tackle issues in traditional systems in traditional systems is introduced by combining large language models (LLMs) and is effective in identifying possible threats as well as filling the semantic gap.

Mamoon M. Saeed, Rashid A. Saeed, Salah Hagahmoodi et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.